Platform & Code (PC4)
Platform & Code
4
Kelly can expose sensitive data by taking advantage of the app's excessive permissions connected to the app's use of location, camera, microphone, storage, etc
Scenario: Kelly can expose sensitive data by taking advantage of the app's excessive permissions connected to the app's use of location, camera, microphone, storage, etc
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
OWASP MASVS: PLATFORM-1
OWASP MASTG: TEST-0024,TEST-0069
SAFECode: 11
Attacks
No attacks registered!